Skip to content
Transparency & Compliance

Subprocessor List

for ImmoVision AI
As of: April 2026

This subprocessor list supplements the contractual documents for ImmoVision AI, in particular the Data Processing Agreement (DPA), service description, and data protection documentation.

It serves to transparently represent those third-party providers and subcontractors that can be used within the framework of service provision for ImmoVision AI, insofar as they process personal data on behalf.

1. General Information

We only use subprocessors to the extent necessary for hosting, infrastructure, AI functions, transcription, support, security, communication, monitoring, or other technical services.

Insofar as subprocessors process personal data on behalf, they are involved on the basis of suitable contractual regulations.

Not every third-party provider is automatically a subprocessor within the meaning of Art. 28 GDPR. Certain providers can – depending on the service area – also be independent controllers or entities acting independently under data protection law. This applies in particular to sub-areas of payment processing, regulatory testing, fraud prevention, or legally mandatory disclosures.

2. Currently Used or Intended Subprocessors

2.1 Hetzner Online GmbH

Service:

Hosting, server, storage, and infrastructure services

Purpose:

Technical provision of the website, platform, data storage, application operation, media delivery, database and server operation

Location of Processing:

Germany / European Union, depending on the infrastructure used

Role:

Subprocessor, insofar as personal data is processed on behalf

Note: Hetzner provides data processing documents and information on data protection and hosting. The specifically used server and storage resources depend on the actual technical architecture of ImmoVision.

2.2 Google Cloud / Google Cloud Platform / Vertex AI

Service:

Cloud, AI, and transcription infrastructure

Purpose:

Processing of content and data within the framework of AI functions, generative text and image processing, structured AI processes, Vertex AI-based functions, and speech/transcription functions, insofar as these are activated on behalf

Location of Processing:

Depending on the booked region and configuration

Role:

Subprocessor, insofar as personal data is processed on behalf

Note: Google publishes a continuously updated subprocessor list for Google Cloud Platform. This also includes activities in connection with AI Platform/Vertex AI, Generative AI Services, and other supporting services. Google also describes there which third-party companies are used, for example, for technical support, data labeling, or special support scenarios.

Insofar as ImmoVision configures Vertex AI regionally, processing can take place in particular in a European or German region, e.g., depending on the specifically booked setup. The actual processing region depends on the productive configuration.

Important note on Speech-to-Text:

On the Google subprocessor page, a separate activity "Voice Transcription" is also mentioned for Speech-to-Text, which is only relevant in special constellations. Google explicitly points out there that human transcription activities only take place with a corresponding opt-in to the Speech-to-Text Data Logging Program. If such an opt-in is not activated in ImmoVision, this should also be documented internally.

2.3 Further Technical Subprocessors

Service:

Security, support, communication, storage, monitoring, integration, or dispatch services

Purpose:

Support of technical operation, error analysis, system monitoring, infrastructure management, or individual system integrations

Location of Processing:

Depending on the service provider used

Role:

Subprocessor, insofar as personal data is processed on behalf

Note: Such service providers are only involved to the extent that this is technically or organizationally necessary. Insofar as new subprocessors are used, this takes place in accordance with the contractual regulations on subprocessing.

3. Services that are not automatically considered subprocessors within the framework of the DPA

3.1 Stripe

Service:

Payment processing, checkout, payment services, fraud prevention, authentication, payment and security infrastructure

Role:

Depending on the processing situation, not exclusively a processor; in certain areas, independent controller or entity acting independently under data protection law

Note: Stripe explicitly describes its own controller activities in the Privacy Center and explains processing operations in particular in connection with fraud prevention, security, regulatory requirements, identity verification, and payment processing. Therefore, Stripe should not be presented across the board as a classic subprocessor in the narrower DPA sense in your documentation, but should be clearly delimited as a payment service provider with partly its own responsibility or an independent role under data protection law.

3.2 Own self-hosted components

These can include in particular:

  • self-hosted video rendering or video creation infrastructure,
  • self-operated media processing,
  • own internal backend and queue systems,
  • own databases, workers, and job orchestration.

These are not considered external subprocessors as long as they run within the infrastructure controlled and operated by the processor itself.

4. Categories of Processing by Subprocessors

Depending on the booked and activated function, subprocessors can process the following data categories in particular on behalf:

  • Master data
  • Contact details
  • Communication data
  • Object and process data
  • User account data
  • Role and authorization data
  • Appointment and status data
  • Content from forms, exposés, microsites, or CRM entries
  • Uploaded media and associated metadata
  • Audio content, transcripts, and structured information derived therefrom, insofar as corresponding functions are activated
  • Technical usage and protocol data, insofar as these serve the order-related provision

5. Change of Subprocessors

We reserve the right to supplement, replace, or technically restructure subprocessors to the extent necessary for service provision, security, scaling, or further development of ImmoVision AI.

Insofar as a data processing agreement exists with a customer, changes take place in accordance with the regulations agreed there, in particular regarding information obligations and objection possibilities.

6. Reference to Current External Documentations

Insofar as providers publish their own, continuously updated documents on data protection, subprocessors, security measures, or cloud regions, these are supplementarily authoritative.

This applies in particular to:

  • Google Cloud Platform / Vertex AI / Gemini / Speech-to-Text.
  • Stripe in the area of payment services, fraud prevention, and Privacy Center.

7. Summary List

Intended / usable as subprocessors

Service:Location of Processing:
1. Hetzner Online GmbH
Hosting, server, storage, and infrastructure services
Germany / EU
2. Google Cloud / Google Cloud Platform / Vertex AI
Cloud, AI, and transcription infrastructure
Region depending on actual configuration
3. Further technical service providers
Security, support, monitoring, integration, or communication services
Only insofar as actually used and necessary

To be classified separately, do not treat across the board as a classic DPA subprocessor

Service:Location of Processing:
1. Stripe
Payment processing, fraud prevention, security and regulatory functions
independent role under data protection law depending on the processing situation

8. Documentation Note for Internal Use

Internally, the following should also be documented:

  • whether Vertex AI is configured regionally in Germany / EU,
  • whether Speech-to-Text Data Logging is deactivated,
  • whether Grounding/Search is deactivated by default,
  • which self-hosted components run purely internally,
  • which further technical service providers are actually used productively.

This does not necessarily all belong literally in the customer version of the subprocessor list, but should be in your internal data protection and system documentation.